CVE-2021-34462Disclosure(microsoft / windows_10)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch microsoft windows_10 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10
  • windows_server_2016
  • windows_server_2019

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
windows_10windows_server_2016windows_server_2019

7 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-03: 2PoC Mentioned / Linked · 2026-07-03: 1Exploit Tool / Code · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 207-03
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • OS Dev@OSdev_
    Disclosure

    CVE-2021-34462 is a great reminder that not every Windows privilege escalation starts with memory corruption. The vulnerability resides in AppXSvc, the service responsible for deploying Microsoft Store applications. During an application reset (e.g., Microsoft Solitaire Collection), AppXSvc recreates user-owned directories and applies security descriptors while running as NT AUTHORITY\SYSTEM. The flaw is a logic error: low-privileged users can modify the DACL of newly created directories during this window, influencing privileged file operations and ultimately achieving SYSTEM privileges. What makes this research particularly interesting is that the exploit relies on understanding AppXSvc internals, Windows ACLs, security descriptors, impersonation, NTFS reparse points, and symbolic link abuse, not a buffer overflow or use-after-free. It's an excellent example of how subtle mistakes in privileged file-system operations can be just as dangerous as classic memory corruption bugs.

    Post summary

    The commentary discloses a NSA‑software privilege‑escalation flaw in Windows AppXSvc, detailing the logic error that allows low‑privileged users to modify DACLs during directory recreation foreach elevating to SYSTEM, while omitting PoC, exploit code, or patch information.

    13044142.7K
    5.0K followersView on X
  • OS Dev@OSdev_
    Exploit

    https://www.pixiepointsecurity.com/blog/nday-cve-2021-34462/

    Post summary

    The blog post announces CVE‑2021‑34462, supplies a PoC/exploit script, details the vulnerability, and references the vendor patch, but makes no claim of ongoing wild exploitation.

    02020351
    5.0K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10---
OSmicrosoftwindows_101607--
OSmicrosoftwindows_101809--
OSmicrosoftwindows_101909--
OSmicrosoftwindows_102004--
OSmicrosoftwindows_1020h2--
OSmicrosoftwindows_1021h1--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_20162004--
OSmicrosoftwindows_server_201620h2--
OSmicrosoftwindows_server_2019---

Explore more